Secure Data Transmission and Privacy-Preserving Path Control for Distributed IoT Based on SDN and Mathematical Optimization
DOI:
https://doi.org/10.4108/eetsis.12426Keywords:
Distributed IoT, secure data transmission, privacy-preserving path control, software-defined networking, threat modeling, trust evaluation, access control, improved genetic algorithmAbstract
INTRODUCTION: Distributed Internet of Things (IoT) communication must jointly satisfy low-latency forwarding, data confidentiality, integrity, access control, and lifecycle protection. Performance-oriented routing may expose sensitive traffic to malicious relays, high-risk links, unauthorized domains, and tampered flow entries.
OBJECTIVES: This study reformulates route optimization as a secure data-transmission and privacy-preserving path-control problem.
METHODS: A three-layer SDN framework combines robust node-reputation and link-risk scoring, security-label matching, attribute-based access control, flow isolation, AES-256-GCM authenticated encryption with ephemeral keys, signed rules, and a diversity-aware improved genetic algorithm. A composite objective integrates delay, loss, utilization, route risk, privacy exposure, and hard policy constraints. A reproducible Python/NetworkX discrete-event simulation compares Dijkstra, ECMP, AODV, OLSR, RPL, classical GA, SDN-TE, trust-aware routing, and two proposed variants.
RESULTS: Across eight independent runs, the full scheme achieved 16.68 ± 1.35 ms normal-operation delay and 98.54 ± 0.21% packet delivery. With 20% malicious nodes, it maintained 98.18 ± 0.39% packet delivery, reduced malicious-link exposure from 20.83% for Dijkstra to 6.67%, eliminated observed plaintext leakage of sensitive payloads in the main runs, and reduced attack-response latency from 722.22 ± 23.53 ms to 130.92 ± 6.34 ms. Paired comparisons against Dijkstra were significant for malicious-link exposure, abnormal-path selection, leakage, packet delivery, and response latency (p < 0.05).
CONCLUSION: The framework converts security and privacy requirements into enforceable routing, cryptographic, access-control, isolation, auditing, and lifecycle policies, enabling reproducible security-performance co-optimization for distributed IoT.
References
[1] Chiang, M., Low, S. H., Calderbank, A. R., & Doyle, J. C. Layering as Optimization Decomposition: A Mathematical Theory of Network Architectures. Proceedings of the IEEE, 2007, 95(1), 255–312. https://doi.org/10.1109/JPROC.2006.887322.
[2] Attkan, A., & Ranga, V. Cyber-physical security for IoT networks: a comprehensive review on traditional, blockchain and artificial intelligence based key-security. Complex & Intelligent Systems, 2022, 8, 3559–3591. https://doi.org/10.1007/s40747-022-00667-z.
[3] Jin, C., Song, Y., Jia, Y., Tan, Q., Yang, R., & Liu, Z. Security and privacy measurement on Chinese consumer IoT traffic based on device lifecycle. Science China Information Sciences, 2026, 69, Article 142107. https://doi.org/10.1007/s11432-025-4609-x.
[4] Dijkstra, E. W. A note on two problems in connexion with graphs. Numerische Mathematik, 1959, 1, 269–271. https://doi.org/10.1007/BF01386390.
[5] Airehrour, D., Gutierrez, J. A., & Ray, S. K. SecTrust-RPL: A secure trust-aware RPL routing protocol for Internet of Things. Future Generation Computer Systems, 2019, 93, 860–876. https://doi.org/10.1016/j.future.2018.03.021.
[6] Djedjig, N., Tandjaoui, D., Medjek, F., & Romdhani, I. Trust-aware and cooperative routing protocol for IoT security. Journal of Information Security and Applications, 2020, 52, Article 102467. https://doi.org/10.1016/j.jisa.2020.102467.
[7] Wang, J. Research and Design of Encryption Standards Based on IoT Network Layer Information Security of Data. EAI Endorsed Transactions on Scalable Information Systems, 2024, 11(5). https://doi.org/10.4108/eetsis.5826.
[8] Vaghela, G., Sanghani, N., & Borisaniya, B. Review on DDoS Attack in Controller Environment of Software Defined Network. EAI Endorsed Transactions on Scalable Information Systems, 2025, 12(1). https://doi.org/10.4108/eetsis.5823.
[9] Hussein, A., Chadad, L., Adalian, N., Chehab, A., Elhajj, I. H., & Kayssi, A. Software-Defined Networking (SDN): the security review. Journal of Cyber Security Technology, 2020, 4(1), 1–66. https://doi.org/10.1080/23742917.2019.1629529.
[10] Nazir, F., Humayun, Q., Ahmad, R. B., & Elias, S. J. Software-Defined Network Testbed Using ZodiacFX a Hardware Switch for OpenFlow. EAI Endorsed Transactions on Scalable Information Systems, 2017, 4(14). https://doi.org/10.4108/eai.25-9-2017.153150.
[11] Ahn, D. J., & Jeong, J. A PMIPv6-based User Mobility Pattern Scheme for SDN-defined Smart Factory Networking. Procedia Computer Science, 2018, 134, 235–242. https://doi.org/10.1016/j.procs.2018.07.166.
[12] Faezi, S., & Shirmarz, A. A Comprehensive Survey on Machine Learning using in Software Defined Networks (SDN). Human-Centric Intelligent Systems, 2023, 3, 312–343. https://doi.org/10.1007/s44230-023-00025-3.
[13] Perkins, C. E., & Royer, E. M. Ad-hoc On-Demand Distance Vector Routing. In Proceedings of the 2nd IEEE Workshop on Mobile Computing Systems and Applications (WMCSA'99), New Orleans, LA, USA, 1999, pp. 90–100. https://doi.org/10.1109/MCSA.1999.749281.
[14] Clausen, T., & Jacquet, P. Optimized Link State Routing Protocol (OLSR). RFC 3626, IETF, October 2003. https://doi.org/10.17487/RFC3626.
[15] Winter, T., Thubert, P., Brandt, A., Hui, J., Kelsey, R., Levis, P., Pister, K., Struik, R., Vasseur, J.-P., & Alexander, R. RPL: IPv6 Routing Protocol for Low-Power and Lossy Networks. RFC 6550, IETF, March 2012. https://doi.org/10.17487/RFC6550.
[16] Chen, J., Zhang, D., Liu, D., & Pan, Z. A Network Selection Algorithm Based on Improved Genetic Algorithm. In 2018 IEEE 18th International Conference on Communication Technology (ICCT), Chongqing, China, 2018, pp. 209–214. https://doi.org/10.1109/ICCT.2018.8600265.
[17] Awan, I. I., Shah, N., Imran, M., Shoaib, M., & Saeed, N. An improved mechanism for flow rule installation in-band SDN. Journal of Systems Architecture, 2019, 96, 1–19. https://doi.org/10.1016/j.sysarc.2019.01.016.
[18] Almotairi, A., Atawneh, S., Khashan, O. A., & Khafajah, N. M. Enhancing intrusion detection in IoT networks using machine learning-based feature selection and ensemble models. Systems Science & Control Engineering, 2024, 12(1), Article 2321381. https://doi.org/10.1080/21642583.2024.2321381.
[19] Sarkar, C., Nambi, A. U. S. N., Prasad, R. V., Rahim, A., Neisse, R., & Baldini, G. DIAT: A Scalable Distributed Architecture for IoT. IEEE Internet of Things Journal, 2015, 2(3), 230–239. https://doi.org/10.1109/JIOT.2014.2387155.
[20] Alnoman, A. A., Sharma, S. K., Ejaz, W., & Anpalagan, A. Emerging Edge Computing Technologies for Distributed IoT Systems. IEEE Network, 2019, 33(6), 140–147. https://doi.org/10.1109/MNET.2019.1800543.
[21] Beilharz, J., Wiesner, P., Boockmeyer, A., Friedenberger, D., Brokhausen, F., Pirl, L., Behnke, I., Polze, A., & Thamsen, L. Continuously Testing Distributed IoT Systems: An Overview of the State of the Art. In Service-Oriented Computing – ICSOC 2021 Workshops, Springer, 2022, pp. 336–350. https://doi.org/10.1007/978-3-031-14135-5_30.
[22] Singh, S., Hosen, A. S. M. S., & Yoon, B. Blockchain Security Attacks, Challenges, and Solutions for the Future Distributed IoT Network. IEEE Access, 2021, 9, 13938–13959. https://doi.org/10.1109/ACCESS.2021.3051602.
[23] Wang, L., & Ranjan, R. Processing Distributed Internet of Things Data in Clouds. IEEE Cloud Computing, 2015, 2(1), 76–80. https://doi.org/10.1109/MCC.2015.14.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Jing Su, Zilin Guo

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.
This is an open access article distributed under the terms of the CC BY-NC-SA 4.0, which permits copying, redistributing, remixing, transformation, and building upon the material in any medium so long as the original work is properly cited.